purplebutter
Back to Library
Access GovernanceInvestigationFree

Org Audit

Review department access dashboards and spot employees with governance risks — orphaned accounts from departed staff, excessive permissions that violate least privilege, and segregation of duties conflicts that no one caught. Submit your findings before the audit deadline.

15 min
IT/Security, Managers

Ready to play?

Put your awareness to the test. See if you can spot the threats before it's too late.

Launch Game

Why This Matters

Periodic access audits are a cornerstone of compliance frameworks — SOX, SOC 2, ISO 27001, and NIST all require regular review of who has access to what. But most organizations treat audits as paperwork rather than security controls, running them quarterly at best and delegating them to managers who lack the context to spot problems.

The most dangerous audit findings are also the easiest to miss. Segregation of duties violations — where one person holds permissions that should require two — are invisible without cross-referencing role definitions. Orphaned accounts from terminated employees persist because offboarding processes fail silently. Excessive permissions accumulate because it's easier to add access than remove it.

Effective access audits require pattern recognition: comparing what access someone has against what their role requires, checking whether terminated employees still have active accounts, and verifying that no single person holds conflicting privileges. The goal isn't perfect access — it's finding the gaps that create real risk.

What You'll Learn

1

Identify segregation of duties violations by cross-referencing employee permissions against role requirements

2

Spot orphaned accounts belonging to departed or transferred employees

3

Recognize excessive permissions that violate the principle of least privilege

4

Practice systematic audit methodology — scanning for patterns rather than reviewing individual permissions in isolation